TeamPCP — Ransomware Profile

TeamPCP is a financially motivated crew that Palo Alto Networks Unit 42 traces to at least September 2025 and says gained wider notice in December 2025 in the wake of the React2Shell campaign. Unit 42 describes an operation with roots in cryptocurrency mining and theft that initially focused on ransomware before shifting toward smash-and-grab supply-chain compromise, poisoning open-source package distribution channels to harvest developer and cloud credentials. Between late February and March 2026 Unit 42 recorded supply-chain attacks affecting the Trivy, KICS, LiteLLM and Telnyx Python SDK projects, alongside an increased posting rate on the group's Telegram channel and dark-web leak site. The group has also claimed a partnership with the Vect ransomware crew in a self-announcement on BreachForums relayed by Unit 42; that claim originates with the actors themselves rather than from independent vendor confirmation.

Also tracked as

PCPcat, ShellForce, DeadCatx3

IntelFusions coverage (7)

Vendor research

Read the full analysis on IntelFusions